Skip to content
Review Open access

A Survey on the Evolution of Automated Penetration Testing Techniques

Aug 2026 · Scientific Journal of Intelligent Systems Research · 0 citations · 21 references

Abstract

As networked systems grow in scale and complexity, traditional penetration testing remains constrained by its reliance on human expertise, substantial labor costs, and limited suitability for continuous assessment. These limitations have driven penetration testing toward greater automation and autonomy.This review examines representative research on automated penetration testing published between 2002 and 2025. It traces the evolution of the field across four major paradigms: formal attack knowledge representation and reasoning, automated vulnerability analysis and attack execution, reinforcement learning-based autonomous decision-making, and large language model-based generative agents.The literature shows a clear shift from predefined, rule-based attack-path generation toward adaptive policy learning and general-purpose reasoning in dynamic environments. Nevertheless, significant challenges remain in real-world generalization, long-horizon planning, persistent knowledge and state management, standardized evaluation, and safe operation.Finally, we discuss emerging directions, including knowledge-enhanced architectures, the integration of reinforcement learning with large language models, human–agent collaboration, and autonomous penetration testing in realistic network environments.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.